View Full Version : AWStats Vulnerability!
Kipkip
February 10th, 2005, 11:42 PM
If you are running AWStats version 6.2 or lower, please upgrade to 6.3. This vulnerability "..allows the execution of arbitrary commands on a server, effectively giving malicious hackers complete control over the machine." Some you may know that http://phpbb.com has been hacked using this expliot. It was not caused by phpbb so as long as you have phpbb 2.0.11, you're good. But if you are running AWStats 6.2 or lower, upgrade now.
Source:
http://www.eweek.com/article2/0,1759,1763152,00.asp
http://phpbb.com/
Imakuni?
February 11th, 2005, 12:02 AM
Fortunatly, I dunped phpBB...
Switch to vB, save your server...
Kipkip
February 11th, 2005, 01:49 AM
Fortunatly, I dunped phpBB...
Switch to vB, save your server...
It is not phpbb's fault. You could use vB(worse in my opinion. Not free, not open-sourced?!?! :shocked: ) or absoulty no forum software at all and you can still be vulnerable if you use AWStats with the version 6.2 or lower.
Imakuni?
February 11th, 2005, 02:06 AM
oh, so its a phpBB addon?
HellishHades
February 11th, 2005, 02:19 AM
oh, so its a phpBB addon?
No. AWStats allows you to view visitors to your site, where other sites link to yours, et cetera.
Kipkip
February 11th, 2005, 08:12 PM
oh, so its a phpBB addon?
It's a stat system like HellishHades said. It's usually in the CPanel under stats or at least that's where mine is.
Imakuni?
February 11th, 2005, 08:21 PM
oh.
*never goes into cPanel except for db's*
PD Wooper
February 13th, 2005, 07:48 PM
Gaah. *kills poweb*
http://pokeden.com/webstats
Geometric-sama
February 24th, 2005, 03:01 AM
This goes in General. *moved